Junglewise Threat Intelligence

sj-tw-abc malicious package with reverse shell

Severity: low · CVSS 3.1 · Published 2020-09-03

Vendors: npm.

Executive brief

The npm package sj-tw-abc contains malicious code that executes scripts to establish a reverse shell on infected systems. Any computer with this package installed should be considered fully compromised, as an attacker gains complete remote control. All credentials, secrets, and keys stored on affected systems must be rotated immediately from a trusted computer, and the package should be removed—though full remediation is not guaranteed without complete system recovery.

Technical details

The sj-tw-abc npm package (all versions) contains embedded malicious code classified as CWE-506 (embedded malicious code). The attack vector is network-based with no authentication or user interaction required; installation and execution of the package is sufficient for exploitation. Upon installation or execution, the malicious code downloads and runs a script that establishes a reverse shell, granting an attacker full command execution and system control. This is a supply chain attack delivered through the npm registry. The only mitigation is complete removal of the package and full system recovery; patch information is not applicable as all versions are compromised and the package should be avoided entirely.

Affected products

  • npm sj-tw-abc all versions

Timeline

  • 2020-09-03: disclosed
  • 2020-08-31: advisory: GitHub reviewed

References